

Private Azure Container Apps: Zero Public Ingress and Managed Identity
Build and validate a private Azure Container Apps platform with Terraform, private endpoints, private DNS, managed identity, Key Vault, Front Door Private Link, and WAF enforcement.

Christos Panagiotidis
7 min read


Azure Network Security Perimeter: Learning Mode to Zero-Trust Enforcement
Build and validate an Azure Network Security Perimeter with Terraform, managed identities, Storage, Key Vault, transition-mode access logs, enforced denials, and explicit Zero Trust recovery.

Christos Panagiotidis
6 min read


Azure Landing Zone Deep Dive: Management Groups, Guardrails, and Subscription Vending
Build and validate an Azure platform landing zone with Terraform, Azure CLI, management groups, inherited policy, RBAC, centralized logging, and safe subscription onboarding.

Christos Panagiotidis
7 min read


Azure Bastion Deep Dive: Secure VM Administration with Entra ID, JIT, and Audit Logs
Administer a private Linux VM through Azure Bastion with no public VM IP, short-lived Microsoft Entra SSH certificates, Defender JIT access, and auditable sessions.

Christos Panagiotidis
8 min read


Azure Private Link Deep Dive: Private Endpoints, DNS, and Hub-Spoke Networking
Build a private Azure SQL path through hub-spoke networking, intentionally break DNS, repair Private DNS links and records, and validate bidirectional resolution with managed identity.

Christos Panagiotidis
11 min read


Azure Policy-as-Code Deep Dive: Terraform, AzAPI, Governance, and Remediation
Build an Azure Policy-as-Code governance lab with Terraform and AzAPI. Stage a North Europe canary, audit before Deny, remediate tags and Blob diagnostics, add a scoped exemption, detect drift, and finish with a clean plan.

Christos Panagiotidis
12 min read








